One downside is that i’ll have no more passkeys. The vault syncing, i can do via SyncThing.
I have used KeePassXC for years. I also use Syncthing which syncs files via my wifi for all devices, including KeePass.
Works like a charm. Occasionally deleting the sync-conflict files in case they appear.
Yes, me too. This also solves 2 problems in 1 shot, since I often want to sync / backup other contents between devices too, so it’s perfect, specially for those of us with a NAS at home.
recently set mine up exactly like this, can vouch
yep, thats the way
It really depend on your threat model, Proton Pass is fine. Of course a self-hosted or local solution will be more privacy friendly but at the cost of being responsable for security and good backups (3,2 1 rule).
There is no black or white regarding privacy. You want to ask yourself what you want to protect from and is the investment worth being sovereign ?
Wdym by “threat model” ?
There have been too many data breaches from cloud-based services to trust another one. I have a Proton account for email and online storage, but I won’t use their password service because it’s cloud based.
https://blog.lastpass.com/posts/notice-of-recent-security-incident
Lastpass leaked their password database in 2022, and bad actors are still using it to access peoples files, stealing passwords and hundreds of thousands of dollars in crypto.
DON’T trust anything important to cloud-based storage or services. Use Keepass. Use Syncthing if you need to keep the database on multiple devices.
(I see other comments using Dropbox. Dropbox = cloud. Don’t store anything security related in the cloud.)
Isn’t protonpass E2EE?
I know I can probably google this. But where are the passwords from Keepass stored? Or what makes it harder to hack?
I still use 1Password because the subscription is still running and I was planning to switch to Proton Pass once that is over. I know 1Password is harder to crack due to their 2nd master key password (or whatever they call it)
Keepass just uses a (local) file, but it expects and can handle if the file is modified externally. That’s important because it means you can store it on a network share, or in some sort of synchronized storage, self hosted or not (next cloud, sync thing, Google drive, whatever). It’s just up to you. If you have it open on your PC and you add an entry on your phone, your PC won’t “overwrite” it, but integrates any changes you’re making there at the same time.
For example the android client has direct support for a long list on storage services for this exact reason.
They are are stored encrypted on your computer if I’m not mistaken
Why not Bitwarden?
deleted by creator
Look I love fully offline concepts just as much as the next person. But what Bitwarden offers me that those other solutions don’t, is to offload some of the mental load long-term. I like privacy but something are exhausting. Pick and choose your battles.
Less hands on maintenance and mental overhead to keep things synced and all services / files up to date. We bitwarden users have other stuff to do. Different priorities.
This is one of the things I decided to keep to the people who do this far more and deeper than I ever could. Their job. Their liability.
All my accounts are encrypted, cloud accessible, or offline accessible. Protected by a giant hash of a master password. It allows me to feel safe and provides the convenience of copy and pasting insane credentials needed in today’s times. Hassle free. Great features. The end.
*potentially even under free account if you choose.
deleted by creator
Here’s the beauty. You can self host it. They give you the option to choose your method. You don’t have to pay they offer free accounts.
deleted by creator
I know it’s not your question, but have you checked out Bitwarden or the alternative Selfhosted Vaultwarden. Bitwarden supports passkeys and vault syncing, and if you are offline you can still access your vault.
https://bitwarden.com/passwordless-passkeys/
Bitwarden also released a AIO selfhosted docker image, but last I checked it’s still not in “official release” status.
Ooh an AIO docker image you say? I may have to look into that.
Its called Bitwarden Unified. Its still in beta at the moment. I have been running this along side Vaultwarden myself.
I like KeepAss.
I use KeepassXC on my computer and Keepass2Android on my phone. Passkeys work fine and are synchronized across my Synology.
Same here, it works well, and the Firefox plugin works well for auto fill, too.
Just make sure KeepassXC is set to Automatically save after every change & Automatically reload the database when modified externally, on the General > Basic Settings screen.
Do both local and cloud backup using keepass or keepassxc, use dropbox or g drive, or private cloud. The .kdbx file is already encrypted when at rest.
I can’t daily drive both.
I think proton is the most blocked by governments group of services in the entire world. To have a backup in .kbdx file sounds at least like a good idea.
Any specific reason that makes Proton Pass less secure? I am curious since I am using both pass and bitwarden at the moment. bitwarden for all my logins and pass for alias + their logins.
I like that KeePass on PC and Android lets you use an autotype feature if autofill isn’t working instead of using copy paste.
you should own your data. So yes
It will always be safer to store sensitive information in a system that you control than in a system that someone else controls. KeePass is easy to setup, it’s easy to use, and it provides excellent protection.
deleted by creator
I think I’ve done the opposite of most. After using keepassx for the last 4 or 5 years I switched to ProtonPass.
Me three.
deleted by creator
i use keepassxc and from protonpass and its great its a lot lot more manuel work but in theory its worth it anything with a internet connection can be hacked
Syncthing is fine and secure, but be absolutely sure you set of some kind of file versioning for the shared folder. at least a trashcan versioning, if not better. protects you against accidental deletion









